Compliance with GDPR

Last updated: 28 Jul 2026

The General Data Protection Regulation (GDPR) is a European Union law that governs how personal data is collected, processed, stored, and protected. It also gives individuals rights over their personal data.

KoboToolbox provides safeguards, features, and contractual terms that support compliance with the GDPR. However, organizations using KoboToolbox are responsible for ensuring that their own data collection and processing activities comply with applicable data protection laws.

Organizations located in the European Union can enter into a data processing agreement (DPA) with Kobo.

Data hosting in the European Union

KoboToolbox offers a European Union server hosted in Ireland. Organizations that require or prefer to store their data in the European Union can create an account on this server.

Accounts, projects, and data cannot be transferred between the Global KoboToolbox Server and the European Union KoboToolbox Server. Organizations that need to keep their data within the European Union should therefore create their accounts on the European Union server from the start.

Using the European Union server can help organizations meet data residency requirements and reduce transfers of personal data outside the European Union.

Responsibilities when collecting personal data

When your organization collects personal data using KoboToolbox, it generally decides why and how that data is processed. This means your organization is responsible for how the data is collected, used, shared, stored, and deleted.

Depending on your project, these responsibilities may include:

  • Collecting only the personal data you need

  • Clearly explaining how the data will be used

  • Obtaining consent when required

  • Limiting access to authorized users

  • Protecting sensitive information

  • Keeping data only for as long as necessary

  • Responding to requests from individuals about their personal data

Using KoboToolbox does not automatically make a project GDPR-compliant. Compliance also depends on how your organization configures and manages each project.

Individual data protection rights

Under the GDPR, individuals may have the right to:

  • Access their personal data

  • Correct inaccurate or incomplete data

  • Request deletion of their data

  • Restrict how their data is processed

  • Receive a copy of their data

  • Object to certain types of processing

  • These rights may be subject to legal requirements and exceptions.

If your personal data was collected through a KoboToolbox form, contact the organization that created or managed the project. That organization is responsible for handling requests related to the data it collected.

Editing and deleting project data

Individuals with a KoboToolbox account can be granted row-level permissions that allow them to view, edit, validate, or delete only specific submissions. These permissions can be limited based on who submitted the data or another column in the data, helping project owners control access to individual records without giving users access to the full dataset.

Users with relevant permissions can delete individual submissions, media files, and whole projects from their KoboToolbox account.

Deleting your KoboToolbox account

You can permanently delete your KoboToolbox account at any time.

Before deleting your account, you must delete all projects you own or transfer their ownership to another user.

To delete your account:

  • Delete or transfer ownership of all projects owned by your account.

  • Open Account Settings.

  • Go to the Profile tab.

  • Click Delete account.

  • Enter your username to confirm the deletion.

The Delete account button will remain disabled while your account owns any projects.

Note: Deleting your account is permanent and cannot be undone.

Security and privacy at KoboToolbox

Kobo regularly reviews and improves the administrative, physical, organizational, and technical safeguards used to protect user information.

Kobo staff do not access project data unless access has been explicitly authorized, such as when a user requests technical support.

Organizations that require greater control over their hosting environment and data can use a KoboToolbox private server or install and manage their own KoboToolbox instance.